mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Paulo Alcantara <pc@manguebit.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-kernel@vger.kernel.org, linux-cifs@vger.kernel.org
Subject: [GIT PULL] smb client fixes for 7.3-rc3
Date: Thu, 10 Sep 2026 12:45:41 -0300	[thread overview]
Message-ID: <bb769b6f6f976d75cbfca3ed00556bde@manguebit.org> (raw)

Linus,

Please consider pulling these smb client fixes for v7.3-rc3. They
address file type corruption in reparse point handling, uid/gid
ownership mapping bugs, heap overflows in DACL rewriting, reference
count leaks, a DFS use-after-free and hardening of legacy smb1 input
validation. All fixes are for stable.

Thanks,
Paulo

----------------------------------------------------------------
The following changes since commit 89a312991dc6e638a36adc43ccb91dbc25504c04:

  Merge tag 'cifs-fixes-7.3-rc2' of https://git.manguebit.org/linux (2026-09-01 13:37:14 -0700)

are available in the Git repository at:

  https://git.manguebit.org/linux.git tags/cifs-fixes-7.3-rc3

for you to fetch changes up to cb26524ef4ac28fcfa554c0656e8dc412c38a8ff:

  smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (2026-09-09 22:06:05 -0300)

----------------------------------------------------------------
smb client fixes for v7.3-rc3

A batch of bug fixes for the smb client:

 - File type corruption fixes in reparse point handling: setting S_IFMT
   bits without clearing the existing type first corrupted the file mode
   (e.g. S_IFREG | S_IFCHR == S_IFLNK). Fixed in the WSL, POSIX and
   native symlink reparse parsers. Also fixes an uninitialized SID
   structure in the POSIX readdir path when parsing fails.

 - Ownership mapping fixes: forceuid/forcegid mount options were
   ignored in several code paths (SID-to-id mapping, WSL extended
   attributes, POSIX extensions getattr), allowing an untrusted server
   to dictate local file ownership despite explicit mount overrides.

 - Heap overflow and overflow fixes in DACL rewriting: replacing short
   SIDs with long ones could overflow the DACL buffer, and the u16
   accumulator for DACL size could wrap around with enough ACEs.

 - Reference count leak fixes in oplock break and deferred close:
   duplicate oplock breaks on a queued work item leaked a
   cifsFileInfo reference, and deferred close had a similar leak when
   requeueing a running work item. Both cause busy-inode oopses on
   unmount.

 - DFS superblock use-after-free fix: the iterator callback stored a
   raw superblock pointer without pinning it, racing with automount
   expiry.

 - One-byte slab OOB read in the native symlink parser when handling
   share-root relative paths.

 - Hardening of legacy SMB1 input: reject userspace-crafted
   cifs.idmap key descriptions that bypass kernel origin checks, and
   validate DataOffset in CIFSSMBRead() to prevent heap info
   disclosure from a malicious server.

 - DFS cache fix: defer metadata updates until target copying
   succeeds to prevent partial-state cache entries on allocation
   failure.

----------------------------------------------------------------
Aohan Mei (1):
      smb: client: reject userspace cifs.idmap descriptions

Bjoern Doebel (4):
      smb: client: avoid leaking refcount in cifs_queue_oplock_break()
      smb: client: avoid leaking refcount when cifs_sb_tlink() fails
      smb: client: fix heap overflow in DACL owner/group rewrite
      smb: client: fail DACL rewrite when the new DACL exceeds 64K

Diego Oliva (2):
      smb: client: reject short READ responses in CIFSSMBRead()
      smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()

Fan Wu (1):
      smb: client: fix cifsFileInfo reference leak in deferred close

Fredric Cover (1):
      smb: client: fill cache fields after populating cache in copy_ref_data()

Karl Mehltretter (1):
      smb: client: pin DFS superblock in iterator callback

Paulo Alcantara (8):
      smb: client: fix uid/gid override in getattr with posix extensions
      smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid
      smb: client: fix WSL reparse point uid/gid override
      smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
      smb: client: fix file type corruption in wsl_to_fattr()
      smb: client: fix file type corruption in posix_reparse_to_fattr()
      smb: client: fix file type corruption in cifs_reparse_point_to_fattr()
      smb: client: fix one-byte OOB read in smb2_parse_native_symlink()

 fs/smb/client/cifsacl.c   | 95 ++++++++++++++++++++++++++++++++---------------
 fs/smb/client/cifssmb.c   | 26 ++++++++++---
 fs/smb/client/dfs_cache.c | 18 ++++-----
 fs/smb/client/file.c      | 22 ++++++++---
 fs/smb/client/inode.c     | 17 ++++++---
 fs/smb/client/misc.c      | 24 ++++++------
 fs/smb/client/readdir.c   | 17 +++++++--
 fs/smb/client/reparse.c   | 33 ++++++++++------
 fs/smb/client/trace.h     |  1 +
 9 files changed, 172 insertions(+), 81 deletions(-)

             reply	other threads:[~2026-09-10 15:45 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10 15:45 Paulo Alcantara [this message]
2026-09-10 21:52 ` pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bb769b6f6f976d75cbfca3ed00556bde@manguebit.org \
    --to=pc@manguebit.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®